2017-01-27 12:05:45 +00:00
|
|
|
// salsa.h - originally written and placed in the public domain by Wei Dai
|
2015-11-05 06:59:46 +00:00
|
|
|
|
2015-11-23 00:17:15 +00:00
|
|
|
//! \file salsa.h
|
|
|
|
//! \brief Classes for Salsa and Salsa20 stream ciphers
|
2015-11-18 20:32:28 +00:00
|
|
|
|
2015-11-05 06:59:46 +00:00
|
|
|
#ifndef CRYPTOPP_SALSA_H
|
|
|
|
#define CRYPTOPP_SALSA_H
|
|
|
|
|
|
|
|
#include "strciphr.h"
|
|
|
|
#include "secblock.h"
|
|
|
|
|
2015-11-18 20:32:28 +00:00
|
|
|
// TODO: work around GCC 4.8+ issue with SSE2 ASM until the exact details are known
|
|
|
|
// and fix is released. Duplicate with "valgrind ./cryptest.exe tv salsa"
|
|
|
|
// "Inline assembly operands don't work with .intel_syntax", http://llvm.org/bugs/show_bug.cgi?id=24232
|
|
|
|
#if CRYPTOPP_BOOL_X32 || defined(CRYPTOPP_DISABLE_INTEL_ASM) || (CRYPTOPP_GCC_VERSION >= 40800)
|
|
|
|
# define CRYPTOPP_DISABLE_SALSA_ASM
|
|
|
|
#endif
|
|
|
|
|
2015-11-05 06:59:46 +00:00
|
|
|
NAMESPACE_BEGIN(CryptoPP)
|
|
|
|
|
2015-11-18 20:32:28 +00:00
|
|
|
//! \class Salsa20_Info
|
2016-09-06 06:51:16 +00:00
|
|
|
//! \brief Salsa20 stream cipher information
|
2015-11-05 06:59:46 +00:00
|
|
|
struct Salsa20_Info : public VariableKeyLength<32, 16, 32, 16, SimpleKeyingInterface::UNIQUE_IV, 8>
|
|
|
|
{
|
2016-12-01 14:37:04 +00:00
|
|
|
CRYPTOPP_STATIC_CONSTEXPR const char* StaticAlgorithmName() {return "Salsa20";}
|
2015-11-05 06:59:46 +00:00
|
|
|
};
|
|
|
|
|
2016-09-06 06:51:16 +00:00
|
|
|
//! \class Salsa20_Policy
|
|
|
|
//! \brief Salsa20 stream cipher operation
|
2015-11-05 06:59:46 +00:00
|
|
|
class CRYPTOPP_NO_VTABLE Salsa20_Policy : public AdditiveCipherConcretePolicy<word32, 16>
|
|
|
|
{
|
|
|
|
protected:
|
|
|
|
void CipherSetKey(const NameValuePairs ¶ms, const byte *key, size_t length);
|
|
|
|
void OperateKeystream(KeystreamOperation operation, byte *output, const byte *input, size_t iterationCount);
|
|
|
|
void CipherResynchronize(byte *keystreamBuffer, const byte *IV, size_t length);
|
|
|
|
bool CipherIsRandomAccess() const {return true;}
|
|
|
|
void SeekToIteration(lword iterationCount);
|
2015-11-18 20:32:28 +00:00
|
|
|
#if (CRYPTOPP_BOOL_X86 || CRYPTOPP_BOOL_X32 || CRYPTOPP_BOOL_X64) && !defined(CRYPTOPP_DISABLE_SALSA_ASM)
|
2015-11-05 06:59:46 +00:00
|
|
|
unsigned int GetAlignment() const;
|
|
|
|
unsigned int GetOptimalBlockSize() const;
|
|
|
|
#endif
|
|
|
|
|
|
|
|
FixedSizeAlignedSecBlock<word32, 16> m_state;
|
|
|
|
int m_rounds;
|
|
|
|
};
|
|
|
|
|
2015-11-18 20:32:28 +00:00
|
|
|
//! \class Salsa20
|
2016-09-06 06:51:16 +00:00
|
|
|
//! \brief Salsa20 stream cipher
|
2016-04-21 08:08:06 +00:00
|
|
|
//! \details Salsa20 provides a variable number of rounds: 8, 12 or 20. The default number of rounds is 20.
|
2016-04-21 04:40:03 +00:00
|
|
|
//! \sa <a href="http://www.cryptolounge.org/wiki/XSalsa20">XSalsa20</a>
|
2015-11-05 06:59:46 +00:00
|
|
|
struct Salsa20 : public Salsa20_Info, public SymmetricCipherDocumentation
|
|
|
|
{
|
|
|
|
typedef SymmetricCipherFinal<ConcretePolicyHolder<Salsa20_Policy, AdditiveCipherTemplate<> >, Salsa20_Info> Encryption;
|
|
|
|
typedef Encryption Decryption;
|
|
|
|
};
|
|
|
|
|
2015-11-18 20:32:28 +00:00
|
|
|
//! \class XSalsa20_Info
|
2016-04-21 04:40:03 +00:00
|
|
|
//! \brief XSalsa20 stream cipher information
|
2015-11-05 06:59:46 +00:00
|
|
|
struct XSalsa20_Info : public FixedKeyLength<32, SimpleKeyingInterface::UNIQUE_IV, 24>
|
|
|
|
{
|
2016-12-01 14:37:04 +00:00
|
|
|
CRYPTOPP_STATIC_CONSTEXPR const char* StaticAlgorithmName() {return "XSalsa20";}
|
2015-11-05 06:59:46 +00:00
|
|
|
};
|
|
|
|
|
2016-09-06 06:51:16 +00:00
|
|
|
//! \class XSalsa20_Policy
|
|
|
|
//! \brief XSalsa20 stream cipher operation
|
2015-11-05 06:59:46 +00:00
|
|
|
class CRYPTOPP_NO_VTABLE XSalsa20_Policy : public Salsa20_Policy
|
|
|
|
{
|
|
|
|
public:
|
|
|
|
void CipherSetKey(const NameValuePairs ¶ms, const byte *key, size_t length);
|
|
|
|
void CipherResynchronize(byte *keystreamBuffer, const byte *IV, size_t length);
|
|
|
|
|
|
|
|
protected:
|
|
|
|
FixedSizeSecBlock<word32, 8> m_key;
|
|
|
|
};
|
|
|
|
|
2015-11-18 20:32:28 +00:00
|
|
|
//! \class XSalsa20
|
2016-09-06 06:51:16 +00:00
|
|
|
//! \brief XSalsa20 stream cipher
|
2015-11-18 20:32:28 +00:00
|
|
|
//! \details XSalsa20 provides a variable number of rounds: 8, 12 or 20. The default number of rounds is 20.
|
2016-04-21 04:40:03 +00:00
|
|
|
//! \sa <a href="http://www.cryptolounge.org/wiki/XSalsa20">XSalsa20</a>
|
2015-11-05 06:59:46 +00:00
|
|
|
struct XSalsa20 : public XSalsa20_Info, public SymmetricCipherDocumentation
|
|
|
|
{
|
|
|
|
typedef SymmetricCipherFinal<ConcretePolicyHolder<XSalsa20_Policy, AdditiveCipherTemplate<> >, XSalsa20_Info> Encryption;
|
|
|
|
typedef Encryption Decryption;
|
|
|
|
};
|
|
|
|
|
|
|
|
NAMESPACE_END
|
|
|
|
|
|
|
|
#endif
|